AWS and Azure cloud penetration testing benchmark
AWS and Azure cloud penetration testing benchmark, real results only: AWS S3 bucket exploitation, Azure Key Vault pentest and Entra ID ROPC MFA bypass, and GCP SSRF metadata token theft, each run autonomously and proven with a working exploit.
Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit. The runs used AWS, Azure and GCP training labs; the model tokenizes real values through the Privacy Gateway so it works on placeholders.
S.03Attack chainsWhat each run proved
Every card opens the long-form write-up. The line above the title is the report's own findings total, its exploited count and severity split.
AWS · huge-logistics S3
Anonymous S3 listing to hardcoded IAM keys to a PCI card-data dump and the CTF flag.
AWS · pwnedlabs EBS/S3
A public unencrypted EBS snapshot and a public bucket mapped by a constrained IAM user, nothing exploited.
Azure · Entra ID tenant
A deleted blob recovered, ROPC minted a token with no MFA, and the directory fully enumerated.
Azure · BloodHound / priv-esc
A helpdesk identity chained through four principals to Global Admin credentials in a storage blob.
Azure · Key Vault (extract)
Three plaintext contractor passwords extracted from Key Vault through over-permissive RBAC.
Azure · Key Vault (pivot)
A stolen Key Vault password reused to authenticate as a contractor and reach customer card data.
GCP · SSRF to metadata
SSRF smuggled through gopher:// to steal a GCP service-account token and empty a bucket.
GCP · public GCS bucket
A bucket name in an HTML comment led to a password-protected backup and 500 PII records.
S.04ResultsCloud runs, finding by finding
Each row links to its long-form write-up and to the raw report in the research corpus.
| Lab / target | Findings | Severity | Exploited | Model | Evidence |
|---|---|---|---|---|---|
| AWS · huge-logistics S3camp_20260802_03bfc675 | 9 | 5C1H2M1L | 5 | claude-opus-4-6 | Write-upReport |
| AWS · pwnedlabs EBS/S3camp_20260802_611cece1 | 9 | 2H5M2L | 0 | claude-opus-4-6 | Write-upReport |
| Azure · Entra ID tenantcamp_20260802_7eee391f | 28 | 11C10H4M3L | 12 | claude-opus-4-6 | Write-upReport |
| Azure · BloodHound / priv-esccamp_20260802_9d245c0c | 19 | 8C6H5M | 11 | claude-opus-4-6 | Write-upReport |
| Azure · Key Vault (extract)camp_20260802_38118fb8 | 16 | 2C6H8M | 6 | claude-opus-4-6 | Write-upReport |
| Azure · Key Vault (pivot)camp_20260802_59e4e905 | 7 | 3C2H2M | 4 | claude-opus-4-6 | Write-upReport |
| GCP · SSRF to metadatacamp_20260802_656007d3 | 4 | 3C1H | 3 | claude-opus-4-6 | Write-upReport |
| GCP · public GCS bucketcamp_20260802_3ced7196 | 5 | 3C1H1M | 4 | claude-opus-4-6 | Write-upReport |
DisclaimerDarkmoon's own benchmark on public cloud training labs.
The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.
S.06More benchmarksKeep exploring the benchmarks
CI/CD and infrastructure pentest benchmark
Jenkins, Redis, PostgreSQL, Terraform, Vault, GitLab and the Docker socket.
IoT firmware penetration testing benchmark
OWASP IoTGoat, static firmware and a live appliance.
Web app pentest benchmark: OWASP Juice Shop
OWASP Juice Shop, black-box, six-campaign escalation.
How Darkmoon compares to other AI pentest tools
Verifiable facts only, with honest credit where competitors lead.
S.07FAQCloud benchmark questions
What does the AWS and Azure cloud penetration testing benchmark cover?
What does the AWS and Azure cloud penetration testing benchmark cover?
Eight autonomous cloud runs across AWS, Azure and GCP: AWS S3 bucket exploitation to an IAM credential chain, Azure Key Vault pentest and Entra ID ROPC MFA bypass to tenant takeover paths, and GCP SSRF metadata token theft. Each run is published with the exact command per finding.
How many cloud vulnerabilities did Darkmoon find?
How many cloud vulnerabilities did Darkmoon find?
Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit, from anonymous S3 listing to a PCI card-data dump and from a Key Vault secret to customer data.
Does the cloud benchmark keep my credentials off the model?
Does the cloud benchmark keep my credentials off the model?
The open source Darkmoon CLI runs the assessment and its Privacy Gateway tokenizes real IPs, hosts and credentials so the model works on placeholders while the real values stay on your perimeter. The web dashboard and the remediation-to-PR loop are paid Pro capabilities.
S.08NextPoint Darkmoon at your own cloud
Open source, self hosted and local first. Run the same AWS, Azure and GCP checks on an account you own. A star helps other teams find it.